codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities
Published Oct 1, 2019
9.8
CRITICALCVSS 3.1
EPSS 5.17%
Description
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.
Affected products
-
- Version Codehaus 1.9.xStatusaffectedConstraints-
- Version
- 7.2.0
Running on/with
- 6.0
- 7.0
- 8.0
No data.
Red Hat Fuse 7.8.0
codehaus
Fixed · RHSA-2020:5568
Red Hat JBoss EAP 7.2
codehaus
Fixed · RHSA-2019:2938
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6
eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el6eap
Fixed · RHSA-2019:2935
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7
eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el7eap
Fixed · RHSA-2019:2936
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8
eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el8eap
Fixed · RHSA-2019:2937
Red Hat BPM Suite 6
codehaus
Out of support scope
Red Hat Decision Manager 7
codehaus
Not affected
Red Hat JBoss A-MQ 6
codehaus
Out of support scope
Red Hat JBoss BRMS 5
codehaus
Out of support scope
Red Hat JBoss BRMS 6
codehaus
Out of support scope
Red Hat JBoss Data Grid 7
codehaus
Not affected
Red Hat JBoss Data Virtualization 6
codehaus
Out of support scope
Red Hat JBoss Enterprise Application Platform 5
codehaus
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
codehaus
Out of support scope
Red Hat JBoss Fuse 6
codehaus
Out of support scope
Red Hat JBoss Fuse Service Works 6
codehaus
Out of support scope
Red Hat JBoss Operations Network 3
codehaus
Out of support scope
Red Hat JBoss SOA Platform 5
codehaus
Out of support scope
Red Hat Mobile Application Platform 4
codehaus
Out of support scope
Red Hat Process Automation 7
codehaus
Not affected
Red Hat Single Sign-On 7
codehaus
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.8.0 | codehaus | Fixed | RHSA-2020:5568 |
| Red Hat JBoss EAP 7.2 | codehaus | Fixed | RHSA-2019:2938 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el6eap | Fixed | RHSA-2019:2935 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el7eap | Fixed | RHSA-2019:2936 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el8eap | Fixed | RHSA-2019:2937 |
| Red Hat BPM Suite 6 | codehaus | Out of support scope | n/a |
| Red Hat Decision Manager 7 | codehaus | Not affected | n/a |
| Red Hat JBoss A-MQ 6 | codehaus | Out of support scope | n/a |
| Red Hat JBoss BRMS 5 | codehaus | Out of support scope | n/a |
| Red Hat JBoss BRMS 6 | codehaus | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | codehaus | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | codehaus | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | codehaus | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | codehaus | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | codehaus | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | codehaus | Out of support scope | n/a |
| Red Hat JBoss Operations Network 3 | codehaus | Out of support scope | n/a |
| Red Hat JBoss SOA Platform 5 | codehaus | Out of support scope | n/a |
| Red Hat Mobile Application Platform 4 | codehaus | Out of support scope | n/a |
| Red Hat Process Automation 7 | codehaus | Not affected | n/a |
| Red Hat Single Sign-On 7 | codehaus | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (28 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 5.17% (0.05175) | 92.20th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.17% (0.05175) | 91.35th | v5 (v2026.06.15) |
| Mar 4, 2026 | 7.24% (0.07240) | 91.46th | v4 (v2025.03.14) |
| Mar 1, 2026 | 1.83% (0.01830) | 82.70th | v4 (v2025.03.14) |
| Feb 4, 2026 | 7.24% (0.07240) | 91.40th | v4 (v2025.03.14) |
| Feb 1, 2026 | 1.83% (0.01830) | 82.58th | v4 (v2025.03.14) |
| Jan 4, 2026 | 7.24% (0.07240) | 91.34th | v4 (v2025.03.14) |
| Jan 1, 2026 | 1.83% (0.01830) | 82.53th | v4 (v2025.03.14) |
| Dec 4, 2025 | 7.24% (0.07240) | 91.27th | v4 (v2025.03.14) |
| Dec 1, 2025 | 1.83% (0.01830) | 82.41th | v4 (v2025.03.14) |
| Nov 28, 2025 | 7.24% (0.07240) | 91.25th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.83% (0.01830) | 81.30th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.36% (0.05362) | 83.11th | v4 (v2025.03.14) |
| Jul 20, 2024 | 1.46% (0.01459) | 86.85th | v3 (v2023.03.01) |
| Jan 25, 2024 | 1.46% (0.01459) | 85.37th | v3 (v2023.03.01) |
| Aug 22, 2023 | 1.48% (0.01479) | 85.12th | v3 (v2023.03.01) |
| Aug 5, 2023 | 1.05% (0.01047) | 82.09th | v3 (v2023.03.01) |
| Jul 21, 2023 | 1.08% (0.01079) | 82.34th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.90% (0.00904) | 80.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.54% (0.01537) | 74.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 17.17% (0.17166) | 93.10th | v2 (v2022.01.01) |
| Feb 3, 2022 | 8.66% (0.08659) | 85.81th | v1 |
| Jan 6, 2022 | 8.66% (0.08659) | 85.64th | v1 |
| Sep 1, 2021 | 2.07% (0.02069) | 77.27th | v1 |
| Jul 30, 2021 | 2.07% (0.02069) | 0.00th | v1 |
| Apr 14, 2021 | 1.86% (0.01865) | 0.00th | v1 |
References (22)
- https://access.redhat.com/security/cve/CVE-2019-10202 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1731271 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10202 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-c27h-mcmw-48hv Advisory
- https://lists.apache.org/thread.html/r0fbf2c60967bc9f73d7f5a62ad3b955789f9a14b950f42e99fca9b4e%40%3Cissues.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0fbf2c60967bc9f73d7f5a62ad3b955789f9a14b950f42e99fca9b4e@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r1edabcfacdad42d3c830464e9cf07a9a489059a7b7a8642cf055542d%40%3Cissues.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r1edabcfacdad42d3c830464e9cf07a9a489059a7b7a8642cf055542d@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r356592d9874ab4bc9da4754592f8aa6edc894c95e17e58484bc2af7a%40%3Cissues.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r356592d9874ab4bc9da4754592f8aa6edc894c95e17e58484bc2af7a@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r500867b74f42230a3d65b8aec31fc93ac390eeae737c91a759ab94cb%40%3Cissues.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r500867b74f42230a3d65b8aec31fc93ac390eeae737c91a759ab94cb@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r5f16a1bd31a7e94ca78eda686179930781aa3a4a990cd55986703581%40%3Cdev.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5f16a1bd31a7e94ca78eda686179930781aa3a4a990cd55986703581@%3Cdev.hive.apache.org%3E
- https://lists.apache.org/thread.html/r6dea2a887f5eb1d68f124d64b14cd1a04f682f06de8cd01b7e4214e0%40%3Cissues.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r6dea2a887f5eb1d68f124d64b14cd1a04f682f06de8cd01b7e4214e0@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rce00a1c60f7df4b10e72fa87827c102f55b074bb91993631df2c21f9%40%3Cdev.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rce00a1c60f7df4b10e72fa87827c102f55b074bb91993631df2c21f9@%3Cdev.hive.apache.org%3E
- https://lists.apache.org/thread.html/refea6018a2c4e9eb7838cab567ed219c3f726dcd83a5472fbb80d8d9%40%3Cissues.flume.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/refea6018a2c4e9eb7838cab567ed219c3f726dcd83a5472fbb80d8d9@%3Cissues.flume.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2019-10202
- https://www.cve.org/CVERecord?id=CVE-2019-10202
Change history (0)
No recorded changes yet.